Advertisement
Promo

Office applications Toolkit

DB2 flaw leaves database defenceless

Martin LaMonica CNET News

Published: 18 Sep 2003 08:55 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A security flaw in Linux editions of IBM's DB2 database could allow unauthorised users to seize control of a database's contents, Big Blue has revealed.

IBM said that the problem affects version 7 of its DB2 database for Linux. The company posted a patch, called FixPak 10a, on its Web site. IBM also is expected to update its usual DB2 version 7 technical support page with the latest fix.

The flaw was uncovered by Boston security company Core Security Technologies, which alerted IBM. Core Security Technologies plans to issue an alert on the vulnerability on Thursday.

Engineers at the security company said the vulnerability, which could allow a person to get "root" privileges to a DB2 database, is simple to exploit. A company employee, for example, with only limited database access rights could trick the system into giving him or her access to the entire data store.

"This flaw is serious because it allows somebody to get control of a system...DB2 is a database, and we assume there is sensitive information in the database," said Paul Paget, chief executive of Core Security Technologies.

The vulnerability allows a hacker to launch a "buffer overflow" attack by sending a long command to a file in the DB2 database, which dictates access privileges, according to Core Security Technologies. With a buffer overflow, hackers can take control of a system and implant unwanted programs.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
41 out of 82 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Discussions

lezlow lezlow

not fussy

Thursday 17 December 2009, 1:59 PM

1 comment
lezlow lezlow

Steorn's perpetual motion machine. Bat...

Thursday 17 December 2009, 1:56 PM

9 comments
Shibley R Shibley R

Correction

Thursday 17 December 2009, 1:54 PM

5 comments

Vista Upgrade Blog

Tinsel on the TARDIS

There were shepherds on the hill, and the Doctor popped his head out of the TARDIS and said "you might want to see this" and they were astounded. WHY do we pay for a TV license?... More

Post a comment

Can I have fries with that? (Consumer...

Licence policies of Tech company's have been for a long time both complicated and 'Dick Turpin-esque', people just click 'I agree' without reading the Agreement. I do the same, but... More

1 comment

This Crap Site

How utterly stupid - I am ranked #40 in the top 100 - as a member of this site..... I mean HOW utterly stupid.... I have done sweet FA, I have only rejoined this site after a 3 or... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters